Tag

Browser Extensions

All articles tagged with #browser extensions

Researcher Demonstrates How Malicious Extensions Can Hijack Browser AI Agents
technology11 days ago

Researcher Demonstrates How Malicious Extensions Can Hijack Browser AI Agents

Security researcher Gal Weizman of Forever Security revealed a new attack vector called 'BragJack' that allows malicious browser extensions to hijack AI assistants in Chrome, Edge, and other Chromium-based browsers. By exploiting the declarativeNetRequest system, attackers can force AI agents to perform actions without additional user clicks, potentially accessing local files, screenshots, and camera feeds. The research led to over $20,000 in bug bounties and two CVEs, with Google and Microsoft confirming patches for the identified vulnerabilities.

Fake Chrome Update Scam Hijacks Trusted Extensions to Deliver Malware
technology1 month ago

Fake Chrome Update Scam Hijacks Trusted Extensions to Deliver Malware

Google warns of a fake Chrome update prompt that can appear on normal websites and push malicious downloads, linked to a hijacked extension (Enable Right Click & Copy - Smart Unlock + OCR) that researchers say was weaponized after acquisition; a broader campaign tied to 19 Chrome/Edge extensions targets users with credential theft and other malware. To stay safe, never update Chrome from a webpage prompt—check for updates via Chrome’s About page, review and remove suspicious extensions and their permissions, enable Enhanced Protection, run full antivirus scans, and consider data-removal services to reduce personal information exposure; restart the browser after removing extensions and monitor for further signs of hijacking.

Crypto-Theft via Trusted-Looking Extensions: 19 Chrome/Edge Add-Ins Harbor Hidden Malware
security1 month ago

Crypto-Theft via Trusted-Looking Extensions: 19 Chrome/Edge Add-Ins Harbor Hidden Malware

Security researchers uncovered 19 Chrome/Edge extensions that mask legitimate functionality while stealing wallet data and draining crypto. The campaign, tracked as Superior by Socket, updates compromised extensions with malicious code after initial benign versions, establishing C2 channels via WebSocket, rotating endpoints, and per‑victim exfiltration. The extensions strip CSP headers to inject 16 malicious modules—ranging from seed-phrase harvesters to credential grabbers—enabling broad data theft. One lead extension, 'Enable Right Click & Copy — Smart Unlock + OCR,' has about 80,000 installs. The attackers reportedly acquired some legitimate extensions or bought them; the operation has been ongoing since February 2024, with broader scope than previously believed. Attribution remains unknown.

Chrome’s MV3 Switch Slams the Door on Traditional Ad Blockers
technology3 months ago

Chrome’s MV3 Switch Slams the Door on Traditional Ad Blockers

Google is switching Chrome from MV2 to Manifest V3, which will end official support for MV2 extensions and effectively disable popular ad blockers such as uBlock Origin; MV3 caps filtering and removes dynamic blocking, limiting ad-blocking effectiveness, though it doesn’t ban blockers outright. A Lite version of uBlock Origin exists with reduced functionality. Other browsers may continue MV2, but Chrome’s transition is slated to roll out with Chrome versions 150–151 this summer.

LinkedIn hit with two lawsuits over alleged covert browser-extension scans
technology6 months ago

LinkedIn hit with two lawsuits over alleged covert browser-extension scans

Two California-backed class-action lawsuits in the Northern District of California allege LinkedIn secretly scans users’ browsers to detect installed extensions and shares related data with third parties; LinkedIn says it discloses such extension scanning in its Privacy Policy to detect abuse and protect site stability, while the suits draw on the BrowserGate report and involve Teamfluence, seeking damages and an injunction.

17 Malicious Browser Extensions Spanning Firefox, Chrome, Edge Exposed
security8 months ago

17 Malicious Browser Extensions Spanning Firefox, Chrome, Edge Exposed

Security researchers at LayerX disclosed 17 malicious browser extensions across Firefox, Chrome and Edge that were downloaded more than 840,000 times and could stay active for years. Mozilla and Microsoft have removed them from official stores; users who installed any should uninstall immediately. The GhostPoster campaign used steganography to hide code and delayed execution to cloak malicious actions, including rewriting HTTP headers, hijacking affiliate traffic, injecting scripts for click fraud and user tracking, auto-solving CAPTCHAs, and granting attackers extended control. Notable extensions included Google Translate in Right Click and Translate Selected Text with Google, with Urban VPN Proxy cited as another high-risk example.

GhostPoster exposed: 17 malicious browser extensions you must delete now
technology8 months ago

GhostPoster exposed: 17 malicious browser extensions you must delete now

Researchers identified 17 Chrome, Firefox, and Edge extensions linked to the GhostPoster campaign. The malware-monitored extensions hide a multi-stage payload that weakens browser protections, opens a backdoor for remote code execution, can hijack traffic and inject tracking scripts, and has reportedly remained active for years before being removed. If you already downloaded any of these extensions, delete them immediately.

GhostPoster Malware Hits 17 Browser Extensions Across Chrome, Firefox, and Edge
technology8 months ago

GhostPoster Malware Hits 17 Browser Extensions Across Chrome, Firefox, and Edge

Researchers warn of the GhostPoster campaign, which distributed 17 malicious browser extensions across Chrome, Firefox, and Edge to monitor activity and hijack affiliate traffic. The extensions load a remote payload via a logo-based loader, and together they have thousands to hundreds of thousands of installs (over 840k in total). Although these extensions can no longer be installed in major browsers, anyone who still has them should delete them immediately, as they can inject scripts, strip HTTP headers, bypass CAPTCHA, and enable click fraud; the campaign appears to have started as early as 2020.

technology8 months ago

GhostPoster malware infiltrates 840,000 users via trusted-looking extensions

Security researchers warn that 22 malicious browser extensions, hiding GhostPoster malware in their logos, have infected over 840,000 users across Chrome, Firefox and Edge since 2020. The extensions spy on activity, inject backdoor scripts, and redirect to fraudulent sites, with potential to install more malware. Mozilla and Microsoft removed the extensions, but affected users must uninstall them manually to stop further damage.

GhostPoster malware resurges via popular browser extensions with 840k installs
technology8 months ago

GhostPoster malware resurges via popular browser extensions with 840k installs

Researchers found 17 GhostPoster-linked extensions in Chrome, Firefox, and Edge totaling about 840,000 installs. The extensions hide malicious JavaScript in their logos to monitor browser activity, hijack affiliate links, and inject invisible iframes for ad and click fraud, pulling a heavily obfuscated payload from an external resource. LayerX reports a more advanced variant that moves the payload into the extension’s background script and stores it inside a bundled image, improving dormancy and evasion. Some extensions have been removed from Mozilla and Microsoft stores; Google has removed them from Chrome Web Store, but users who installed them may still be at risk. The campaign originated on Edge and later spread to other browsers, and the researchers say it remains active.

Massive Browser Extension Malware Campaigns Expose Global Cybersecurity Threats
cybersecurity9 months ago

Massive Browser Extension Malware Campaigns Expose Global Cybersecurity Threats

The DarkSpectre threat actor, linked to China, has exposed a series of malicious browser extensions across Chrome, Edge, and Firefox, affecting over 8.8 million users worldwide. These extensions, including ShadyPanda, GhostPoster, and The Zoom Stealer, are designed for data theft, corporate espionage, and meeting information harvesting, often masquerading as legitimate tools for video conferencing and utilities. The campaigns have been active for over seven years, with some extensions still in the trust-building phase, posing significant risks to user privacy and corporate security.

Popular Browser Extensions Harvest and Sell AI Chat Data
technology9 months ago

Popular Browser Extensions Harvest and Sell AI Chat Data

Research reveals that four popular browser extensions, including Urban VPN Proxy, have been secretly harvesting and transmitting users' AI chat conversations to third parties, despite privacy claims. These extensions inject scripts into AI platforms like ChatGPT and Meta AI, capturing and sending chat data without user consent, raising significant privacy concerns. Users are advised to uninstall these extensions immediately to protect their data.

Browser extensions transform nearly 1 million browsers into website-scraping bots
technology1 year ago

Browser extensions transform nearly 1 million browsers into website-scraping bots

Nearly 1 million browser extensions across Chrome, Firefox, and Edge have been exploited to covertly turn browsers into web scraping bots for a paid service, leveraging a JavaScript library called MellowTel-js. These extensions, used for various benign purposes, are being used to bypass security protections and scrape websites on behalf of paying clients, including advertisers, raising significant security concerns.

Shield Yourself from Meta's New Privacy Threat
privacy1 year ago

Shield Yourself from Meta's New Privacy Threat

Researchers uncovered Meta's new tracking technique exploiting a loophole to spy on users' web browsing, bypassing security protections on Android devices. This highlights the ongoing privacy risks posed by Meta's surveillance practices. To protect yourself, use privacy-focused browsers like Brave or DuckDuckGo, delete untrusted apps, install privacy extensions like Privacy Badger, and limit Meta's data use. The incident underscores the need for stronger privacy laws and better browser protections, especially in Chrome, which currently lacks robust tracker blocking.